When your organisation joins Risk Ledger as a client, the platform automatically creates a set of six template policies for you. These give you a strong starting point for managing your supply chain, and you can edit them at any time to match your organisation's own security requirements.
This article explains how the template policies are applied and lists the controls included in each one.
š” The control references in this article reflect the Risk Ledger framework as of the August 2026 framework update. If you have edited your template policies since they were created, your own policies may differ from the templates shown here.
How template policies are applied
Each template policy is linked to one supplier tag. When you tag a supplier on the Supplier Overview page with a criticality, confidentiality or PII tag, the matching policy is applied to that supplier automatically. The Base Policy applies to every supplier.
Policies stack. For example, a supplier tagged as Critical, Highly Confidential and Holds PII will have four policies applied: the Base Policy, Critical Suppliers, Suppliers with Highly Confidential Data and Suppliers with PII. Where more than one policy requires the same control, Risk Ledger uses the highest requirement.
Each tag drives a different type of control:
Criticality drives controls that protect a supplier's availability and system integrity.
Confidentiality drives controls that protect the data a supplier holds.
Holds PII drives data privacy controls.
Template policies at a glance
Policy | Applies to | Focus | Controls |
Base Policy | Every supplier | Baseline compliance and security | 34 |
Critical Suppliers | Criticality: Critical | Availability and integrity | 139 |
Important Suppliers | Criticality: Important | Availability and integrity | 100 |
Suppliers with Highly Confidential Data | Confidentiality: Highly Confidential | Data protection | 134 |
Suppliers with Confidential Data | Confidentiality: Confidential | Data protection | 98 |
Suppliers with PII | Holds PII | Data privacy | 145 |
Framework domains
Controls are referenced by their domain letter and number. For example, D12 is control 12 in the IT Operations domain.
Letter | Domain |
A | Security Governance |
B | Security Certifications |
C | HR Security |
D | IT Operations |
E | Software Development |
F | Network & Cloud Security |
G | Physical Security |
H | Business Resilience |
I | Supply Chain Management |
J | Data Protection |
K | Artificial Intelligence |
XA | Financial Risk |
1. Base Policy
Makes sure every supplier meets the base requirements around compliance and security.
Applies to: Every supplier
āNumber of controls: 34
Domain | Controls |
A. Security Governance | 2, 3, 6, 10, 15, 19 |
B. Security Certifications | 6 |
C. HR Security | 2, 3, 4 |
D. IT Operations | 12, 13, 19, 29, 30, 32 |
E. Software Development | 2, 3 |
F. Network & Cloud Security | 1 |
G. Physical Security | 1 |
H. Business Resilience | 1, 5, 8, 9 |
I. Supply Chain Management | 6 |
J. Data Protection | 2, 3, 5 |
XA. Financial Risk | 18, 19, 20, 21, 22, 23 |
2. Critical Suppliers
Covers system availability and integrity controls for suppliers that are critical to your organisation.
Applies to: Suppliers with a criticality of Critical
āNumber of controls: 139
Domain | Controls |
A. Security Governance | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 13, 14, 15, 16, 17, 18, 19, 20, 21, 24, 26 |
C. HR Security | 1, 2, 3, 4, 5 |
D. IT Operations | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 25, 26, 27, 29, 30, 32, 33, 34, 36 |
E. Software Development | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15 |
F. Network & Cloud Security | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 14, 15, 16, 17, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34 |
G. Physical Security | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 |
H. Business Resilience | 1, 2, 3, 4, 5, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 21, 22 |
I. Supply Chain Management | 2, 3, 4, 5, 6 |
K. Artificial Intelligence | 6, 7 |
3. Important Suppliers
Covers system availability and integrity controls for suppliers that are important to your organisation.
Applies to: Suppliers with a criticality of Important
āNumber of controls: 100
Domain | Controls |
A. Security Governance | 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 15, 16, 17, 19, 21 |
C. HR Security | 1, 2, 3, 4, 5 |
D. IT Operations | 1, 2, 4, 5, 6, 11, 12, 13, 16, 17, 18, 19, 20, 22, 23, 25, 26, 29, 30, 32, 33, 34 |
E. Software Development | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15 |
F. Network & Cloud Security | 1, 2, 3, 4, 7, 9, 10, 14, 19, 20, 23, 25, 27, 28, 29, 30, 31, 32, 34 |
G. Physical Security | 1, 4, 5, 8, 10 |
H. Business Resilience | 1, 2, 3, 4, 5, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16 |
I. Supply Chain Management | 2, 3, 4, 5, 6 |
4. Suppliers with Highly Confidential Data
Covers data protection controls for suppliers that hold highly confidential data.
Applies to: Suppliers with a confidentiality of Highly Confidential
āNumber of controls: 134
Domain | Controls |
A. Security Governance | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 23, 24, 25, 26 |
B. Security Certifications | 1 |
C. HR Security | 1, 2, 3, 4 |
D. IT Operations | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 25, 26, 27, 29, 30, 31, 33, 36, 37 |
E. Software Development | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15 |
F. Network & Cloud Security | 1, 2, 3, 4, 5, 6, 7, 8, 10, 11, 14, 15, 16, 17, 19, 20, 21, 22, 23, 24, 25, 26, 27, 29, 30, 31, 32, 33, 34 |
G. Physical Security | 1, 2, 3, 4, 5, 6, 7, 8, 9, 11 |
H. Business Resilience | 1, 2, 3, 4, 5, 7, 8, 9, 10, 15, 21, 22 |
I. Supply Chain Management | 2, 3, 4, 5, 6 |
K. Artificial Intelligence | 6, 7 |
5. Suppliers with Confidential Data
Covers data protection controls for suppliers that hold confidential data.
Applies to: Suppliers with a confidentiality of Confidential
āNumber of controls: 98
Domain | Controls |
A. Security Governance | 2, 3, 4, 6, 7, 8, 9, 10, 11, 12, 15, 16, 17, 19, 21, 23, 24, 25 |
C. HR Security | 1, 2, 3, 4 |
D. IT Operations | 1, 2, 3, 4, 5, 6, 8, 9, 10, 11, 12, 13, 17, 18, 19, 22, 23, 25, 26, 27, 29, 30, 31, 33, 36, 37 |
E. Software Development | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15 |
F. Network & Cloud Security | 1, 2, 3, 10, 11, 14, 16, 17, 19, 20, 23, 25, 29, 30, 31, 32, 34 |
G. Physical Security | 1, 4, 5, 8, 11 |
H. Business Resilience | 1, 2, 3, 4, 5, 7, 8, 9, 10 |
I. Supply Chain Management | 2, 3, 4, 5, 6 |
6. Suppliers with PII
Covers data privacy and protection controls for suppliers that hold Personally Identifiable Information (PII).
Applies to: Suppliers tagged as Holds PII
āNumber of controls: 145
Domain | Controls |
A. Security Governance | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 23, 24, 25 |
B. Security Certifications | 1 |
C. HR Security | 1, 2, 3, 4 |
D. IT Operations | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 25, 26, 27, 29, 30, 31, 32, 33, 34, 36, 37 |
E. Software Development | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15 |
F. Network & Cloud Security | 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 14, 15, 19, 20, 21, 22, 23, 24, 25, 26, 27, 29, 30, 31, 32, 33, 34 |
G. Physical Security | 1, 2, 3, 4, 5, 8, 9, 11 |
H. Business Resilience | 1, 2, 3, 4, 5, 7, 8, 9, 10, 15, 21, 22 |
I. Supply Chain Management | 1, 2, 3, 4, 5, 6 |
J. Data Protection | 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 15, 16 |
Customising your policies
The template policies are a starting point. You can edit, add or remove controls, create new policies, or apply policies to your own custom labels. To learn how, read How to setup a policy.
Your policies can also be used to build a Flexible Framework assessment for a supplier, so they only answer the controls you require. Read How does the Flexible Framework work? for more detail.
š” If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.
